Bugtraq: by author

50 messages starting Dec 10 19 and ending Dec 19 19
Date index | Thread index | Author index


Advisories

CVE-2019-17554 - Apache Olingo OData 4.0 - XML External Entity Resolution (XXE) Advisories (Dec 10)

Alexander Minozhenko

Confluence Server and Data Center Security Advisory - 2019-12-18 - CVE-2019-15006 Alexander Minozhenko (Dec 19)

Alphan YAVAS

External Service Interaction (DNS) on Skype for Business Alphan YAVAS (Dec 06)
Microsoft Exchange Server, External Service Interaction (DNS) Alphan YAVAS (Dec 29)
External Service Interaction (DNS) on Skype for Business Alphan YAVAS (Dec 06)

apparitionsec

NAPC Xinet Elegant 6 Asset Library Web Interface v6.1.655 Pre-Auth SQL Injection 0Day CVE-2019-19245 apparitionsec (Dec 02)
Microsoft Windows Media Center XXE MotW Bypass (Anniversary Edition) apparitionsec (Dec 03)
Microsoft Excel 2016 v1901 Import Error XML External Entity Injection apparitionsec (Dec 02)
Microsoft Windows .Group File / URL Field Code Execution apparitionsec (Dec 31)
Max Secure Anti Virus Plus v19.0.4.020 Insecure Permissions CVE-2019-19382 apparitionsec (Dec 02)

Apple Product Security

APPLE-SA-2019-12-10-2 iOS 12.4.4 Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-4 watchOS 5.3.4 Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-8 watchOS 6.1.1 Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-6 Safari 13.0.4 Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-3 macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-5 tvOS 13.3 Apple Product Security (Dec 11)
APPLE-SA-2019-12-10-7 Xcode 11.3 Apple Product Security (Dec 11)

john

BeeGFS Privilege Escalation (CVE-2019-15897) john (Dec 05)

Kevin Kotas

CA20191218-01: Security Notice for CA Client Automation Agent for Windows Kevin Kotas (Dec 25)
CA20191209-01: Security Notice for CA Nolio (Release Automation) Kevin Kotas (Dec 10)

Moritz Muehlenhoff

[SECURITY] [DSA 4582-1] davical security update Moritz Muehlenhoff (Dec 16)
[SECURITY] [DSA 4583-1] spip security update Moritz Muehlenhoff (Dec 16)
[SECURITY] [DSA 4590-1] cyrus-imapd security update Moritz Muehlenhoff (Dec 19)
[SECURITY] [DSA 4595-1] debian-lan-config security update Moritz Muehlenhoff (Dec 29)
[SECURITY] [DSA 4592-1] mediawiki security update Moritz Muehlenhoff (Dec 29)
[SECURITY] [DSA 4585-1] thunderbird security update Moritz Muehlenhoff (Dec 16)
[SECURITY] [DSA 4589-1] debian-edu-config security update Moritz Muehlenhoff (Dec 18)
[SECURITY] [DSA 4596-1] tomcat8 security update Moritz Muehlenhoff (Dec 29)
[SECURITY] [DSA 4594-1] openssl1.0 security update Moritz Muehlenhoff (Dec 29)
[SECURITY] [DSA 4579-1] nss security update Moritz Muehlenhoff (Dec 10)
[SECURITY] [DSA 4580-1] firefox-esr security update Moritz Muehlenhoff (Dec 10)
[SECURITY] [DSA 4593-1] freeimage security update Moritz Muehlenhoff (Dec 29)

Qualys Security Advisory

Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726) Qualys Security Advisory (Dec 12)
Authentication vulnerabilities in OpenBSD Qualys Security Advisory (Dec 05)

Salvatore Bonaccorso

[SECURITY] [DSA 4586-1] ruby2.5 security update Salvatore Bonaccorso (Dec 17)
[SECURITY] [DSA 4591-1] cyrus-sasl2 security update Salvatore Bonaccorso (Dec 25)
[SECURITY] [DSA 4584-1] spamassassin security update Salvatore Bonaccorso (Dec 16)
[SECURITY] [DSA 4587-1] ruby2.3 security update Salvatore Bonaccorso (Dec 17)
[SECURITY] [DSA 4581-1] git security update Salvatore Bonaccorso (Dec 10)
[SECURITY] [DSA 4565-2] intel-microcode security update Salvatore Bonaccorso (Dec 16)

Sebastien Delafond

[SECURITY] [DSA 4588-1] python-ecdsa security update Sebastien Delafond (Dec 18)

SEC Consult Vulnerability Lab

SEC Consult SA-20191211-0 :: File Extension Spoofing in Windows Defender Antivirus SEC Consult Vulnerability Lab (Dec 12)
SEC Consult SA-20191203-0 :: Multiple vulnerabilites in Fronius Solar Inverter Series SEC Consult Vulnerability Lab (Dec 03)
SEC Consult SA-20191202-0 :: Multiple Critical Vulnerabilities in SALTO ProAccess SPACE SEC Consult Vulnerability Lab (Dec 02)

simon . moser

[SYSS-2019-045] "Scoutnet Kalender" for WordPress - Cross-Site Scripting simon . moser (Dec 10)

Slackware Security Team

[slackware-security] tigervnc (SSA:2019-354-02) Slackware Security Team (Dec 25)
[slackware-security] wavpack (SSA:2019-353-01) Slackware Security Team (Dec 19)
[slackware-security] openssl (SSA:2019-354-01) Slackware Security Team (Dec 25)
[slackware-security] mozilla-firefox (SSA:2019-337-01) Slackware Security Team (Dec 04)

Vulnerability Lab

Deutsche Bahn Ticket Vending Machine Windows XP - Local Kiosk Privilege Escalation Vulnerability Vulnerability Lab (Dec 19)